CISA adds the two Citrix flaws to the KEV catalog and mandates a September 30 fix for federal agencies
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog and invoked Binding Operational Directive (BOD) 26-04 to order Federal Civilian Executive Branch (FCEB) agencies to secure all vulnerable Citrix appliances by September 30. CISA warned that "malicious actors are exploiting at least some of these vulnerabilities" and "urges users and administrators to review Citrix's advisories."
Citrix confirms active exploitation, urges immediate patching and forensic caution
Citrix released security updates days after national cybersecurity agencies, IT suppliers, and security teams privately began advising customers to shut down NetScaler appliances. In a Sunday blog post, Citrix said "Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible."
The company simultaneously published "generic Indicators of Compromise" through NetScaler Console but cautioned that those IoCs "might be of limited forensic value and might fail to identify actual compromises." Citrix advised customers "to retain the services of experienced forensic investigators" and recommended, where possible, checking for indications of compromise prior to patching because "updates may result in loss of forensic visibility."
Notably, Citrix's confirming blog post included a 'noindex' meta tag instructing search engines not to index the page.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhat the two vulnerabilities do and how they differ
Both CVE-2026-88771 and CVE-2026-88772 permit unauthenticated remote code execution on vulnerable NetScaler appliances, according to Citrix. The first vulnerability affects all NetScaler ADC and NetScaler Gateway deployments with default configurations. The second requires Datagram Transport Layer Security (DTLS) to be enabled; Citrix noted that "DTLS is toggled on by default on VPN virtual servers."
Citrix also warned the vulnerabilities "vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions."
Internet exposure, prior Citrix incidents, and uncertainty about the true attack surface
Shadowserver's tally of more than 23,000 IP addresses with NetScaler fingerprints underscores the potential reach of the flaws, but the record is incomplete: there is no information in the public reporting on how many of those hosts are honeypots, have already been patched, or have vulnerable configurations. Citrix has provided IoCs via NetScaler Console to assist investigations, but explicitly warned those IoCs may miss compromises.
The two vulnerabilities are the latest in a string of exploitable Citrix flaws this year. In March, Citrix urged administrators to patch CVE-2026-3055 and CVE-2026-4368 days before they were observed in attacks. In early September, attackers began exploiting an authentication bypass (CVE-2026-19490) that Citrix had patched in mid‑August. Since November 2021, CISA has flagged 26 actively exploited Citrix vulnerabilities, including six abused by ransomware gangs.
How Federal agencies, security teams, and threat actors are responding
- Federal agencies: FCEB agencies are required under BOD 26-04 to secure vulnerable Citrix appliances by September 30 and must therefore prioritize installation of Citrix's updated versions or other mitigations identified in Citrix advisories.
- Security teams and responders: Security teams are urged to review Citrix advisories, check for indications of compromise prior to applying updates where possible, use the IoCs published through NetScaler Console, and consider retaining experienced forensic investigators because Citrix warned IoCs may be limited in forensic value.
- Threat actors: The reporting shows attackers have already exploited the two newly cataloged flaws in zero‑day attacks; earlier in the year threat actors exploited other NetScaler vulnerabilities, and CISA's KEV list reflects continued active abuse of Citrix products.
The record in these disclosures is straightforward: two remote‑code‑execution flaws, public exploits observed in the wild, Citrix advisories and IoCs that come with caveats, Shadowserver's broad fingerprint count, and a statutory deadline imposed on federal agencies. With CISA's KEV listing and the BOD deadline, organizations that fall under the federal directive must move to apply Citrix's updates and, where compromise is suspected, preserve forensic evidence before updating.
Original story: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/




